Stored Cross-Site Scripting in Mobile Security Framework by MobSF
CVE-2024-53999

5.4MEDIUM

Key Information:

Vendor

MobSF

Vendor
CVE Published:
3 December 2024

What is CVE-2024-53999?

The Mobile Security Framework (MobSF) suffers from a Stored Cross-Site Scripting vulnerability that arises due to improper handling of script files uploaded via the filename parameter. This flaw allows attackers to insert malicious scripts when the 'Diff or Compare' feature is utilized, which can lead to unauthorized actions being executed in the context of the affected user session. This issue has been addressed in version 4.2.9, providing users with an essential update to secure their applications effectively.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.